[fw-wiz] IP aliasing behind a PIX

From: Don Owens (don@xlogistics.com)
Date: 01/18/03


From: Don Owens <don@xlogistics.com>
To: firewall-wizards@honor.icsalabs.com
Date: Sat Jan 18 21:42:01 2003

Hi guys,

I'm overloading interfaces on Solaris and Linux boxen to have multiple
IPs (same network though) behind a PIX firewall. From within the
network, the aliases work fine (i.e., the machines are accessible using
the aliased IPs). However, when trying to get to them from outside the
network, the IPs are unreachable. These are public IPs and the routing
works fine for each IP if that IP is the main IP of the box. If I swap
the IP of one of the aliases with the main IP, that IP is then
reachable. Then the alias works as well until I reboot the PIX.

It seems to me this has to be the PIX, as I have not had this problem in
the past using access lists on routers as firewalls. Has anyone else
seen this problem? Am I missing a simple setting on the PIX or
something?

Any ideas?

Don

--
Don Owens
don@xlogistics.com
www.xlogistics.com
Express Logistics
48541 Warm Springs Blvd., Ste. 505
Fremont, CA 94539


Relevant Pages

  • RE: [fw-wiz] Re: IP aliasing behind a PIX
    ... > network behind the PIX, but ... >> IPs behind a PIX firewall. ... >> network, the aliases work fine (i.e., the machines are accessible using ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Re: IP aliasing behind a PIX
    ... > network behind the PIX, but ... >> IPs behind a PIX firewall. ... >> network, the aliases work fine (i.e., the machines are accessible using ...
    (Firewall-Wizards)
  • [fw-wiz] Re: IP aliasing behind a PIX
    ... network behind the PIX, but ... Once I added a line with the correct netmask, the aliases began ... > IPs behind a PIX firewall. ...
    (Firewall-Wizards)
  • IP alias Networking Errors.
    ... When the next group of IP were assigned to me, and I set them as aliases on ... 'Gateway' IP that was given to me when I got this set of IPs. ... I was given a new 'Network Number' and 'Gatweway' number ... Server Admin ...
    (freebsd-questions)
  • Re: Cisco VPN Client config on 515
    ... destination IPs etc) but this is my protected network. ... nothing inbetween will filter the packets, ... at your PIX interface if they are addressed to any of your public IPs. ...
    (comp.dcom.sys.cisco)